6.8

CVE-2014-1901

Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp.  NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Y-cam ≫ Yceb03 Firmware Version 4.30
   Y-cam ≫ Yceb03
Y-cam ≫ Ycb004 Firmware Version 4.30
   Y-cam ≫ Ycb004
Y-cam ≫ Ycb002 Firmware Version 4.30
   Y-cam ≫ Ycb002
Y-cam ≫ Ycbl03 Firmware Version 4.30
Y-cam ≫ Ycblb3 Firmware Version 4.30
Y-cam ≫ Yck002 Firmware Version 4.30
   Y-cam ≫ Yck002
Y-cam ≫ Ycblhd5 Firmware Version 4.30
   Y-cam ≫ Ycblhd5
Y-cam ≫ Ycw003 Firmware Version 4.30
   Y-cam ≫ Ycw003
Y-cam ≫ Ycw001 Firmware Version 4.30
   Y-cam ≫ Ycw001
Y-cam ≫ Ycw002 Firmware Version 4.30
   Y-cam ≫ Ycw002
Y-cam ≫ Ycb001 Firmware Version 4.30
   Y-cam ≫ Ycb001
Y-cam ≫ Ycw004 Firmware Version 4.30
Y-cam ≫ Yck003 Firmware Version 4.30
   Y-cam ≫ Yck003
Y-cam ≫ Yck004 Firmware Version 4.30
   Y-cam ≫ Yck004
Y-cam ≫ Ycb003 Firmware Version 4.30
   Y-cam ≫ Ycb003
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.666
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.y-cam.com/y-cam-security-fix/
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2014-007/?fid=3850